Also known as: CYBORG SPIDER
GOLD BURLAP is a group of financially motivated criminals responsible for the development of the Pysa ransomware, also referred to as Mespinoza. Pysa is a cross-platform ransomware with known versions written in C++ and Python. As of December 2020, approximately 50 organizations had reportedly been targeted in Pysa ransomware attacks. The operators leverage 'name and shame' tactics to apply additional pressure to victims. As of January 2021, CTU researchers had found no Pysa advertisements on underground forums, which likely indicates that it is not operated as ransomware as a service (RaaS).
Targeted Sectors
Executive Summary
GOLD BURLAP, also known as CYBORG SPIDER, is a financially motivated threat actor group responsible for the development and deployment of the Pysa ransomware (also referred to as Mespinoza). The group primarily targets healthcare organizations, leveraging sophisticated tactics such as 'name and shame' strategies to pressure victims into paying ransoms. While no advertisements for Pysa have been found on underground forums, indicating it is not a ransomware-as-a-service (RaaS) product, the group remains active and poses a significant threat to critical infrastructure.
Goals & Targeting
GOLD BURLAP's primary strategic objective is financial gain through ransomware activities. While their targeting focus has included healthcare organizations due to the sector's sensitive data and potential for high-ransom demands, the group’s broader targeting patterns remain unclear. Their victims appear to be selected based on ease of access rather than specific geopolitical or industry-related factors. The use of 'name and shame' tactics indicates a sophisticated understanding of victim psychology and pressure points.
Enhanced Description
GOLD BURLAP is a cybercriminal organization specializing in the development and operation of the Pysa ransomware. This ransomware is cross-platform, with known versions developed using C++ and Python. As of December 2020, approximately 50 organizations across various industries were reported to have fallen victim to Pysa attacks. The group's primary motivation appears to be financial gain, achieved through the encryption of victims' data and subsequent demands for payment in exchange for decryption keys or files. The operators behind GOLD BURLAP employ 'name and shame' tactics to increase pressure on targeted organizations, often publicly naming uncooperative victims and sharing stolen data to further coerce payments. This approach is particularly concerning for healthcare organizations, which may face additional risks to patient trust and data privacy. The lack of Pysa advertisements on underground forums suggests that the group operates independently rather than as a RaaS offering, implying a more centralized and controlled operation.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
GOLD BURLAP's campaigns typically involve targeted attacks against healthcare organizations, leveraging phishing or remote access vectors to deploy Pysa. The group operates with a moderate operational tempo, focusing on stealth and persistence to avoid detection. Notable past operations include the December 2020 wave of attacks affecting healthcare entities. Campaigns often involve the encryption of critical systems followed by the publication of victim data to maximize pressure on organizations. Despite their relative lack of visibility in underground forums, the group’s focus on a specific geographic or sectoral targeting strategy remains underdetailed in available intelligence.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The available intelligence on GOLD BURLAP is limited, particularly in detailing their initial access methods or specific tradecraft. While the existence of Pysa ransomware and related victim data is well-documented, gaps remain in understanding their full suite of tools, operational strategies beyond healthcare targeting, and long-term goals. The group's lack of visibility on underground forums adds to the uncertainty surrounding their true capabilities and potential evolution.
No techniques linked yet.
No tools linked yet.
No campaigns linked yet.
No observed data linked yet.
No IOCs linked yet.
No references recorded yet.
0
Techniques
0
Tools
0
Campaigns
0
IOCs
0
Observed Data
0
Tactics